-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
Cyber Diligence for the Decision in Front of You
The work scales with the stage of the transaction. Early review identifies what is visible and what remains unknown; deeper diligence verifies the controls and builds the post-close plan.
5-day initial risk review
A bounded early view of available evidence, visible exposure, disclosed incidents and obligations, material red flags, and the questions that require management access.
Management-access diligence
Controls, architecture, critical data, resilience, compliance, third parties, key-person dependencies, and remediation needs reviewed at the depth the transaction allows.
Decision-ready reporting
An investment-committee narrative that separates verified facts, unresolved evidence gaps, plausible exposure, and the decisions the deal team needs to make.
100-day security planning
A sequenced post-close roadmap with priorities, owners, dependencies, and governance so diligence findings become managed work rather than shelfware.
Engagement path: 5-day Initial Risk Review, deeper diligence when management access is available, and an optional 100-day post-close security plan.
Evidence, with Limits Stated
Theodolite can accelerate evidence review. It does not manufacture certainty.
When the target environment and current source coverage fit, Theodolite can help organize verified control evidence, implementation status, findings, and priorities for the diligence team.
Interviews, documents, source access, and operator judgment still determine what can be concluded. The deliverable separates verified facts from assumptions and missing evidence so the investment committee can see both the risk and the confidence behind the assessment.
Review current source coverage →How It Works
-
5-Day Initial Risk Review
A bounded early view for the deal team: available evidence, visible exposure, disclosed incidents and obligations, material red flags, and the questions that need management access.
-
Management-Access Diligence
Go deeper into controls, architecture, data, resilience, compliance, third parties, key-person dependencies, and remediation requirements once the transaction process allows it.
-
Investment Decision and 100-Day Plan
Translate the findings into an investment-committee narrative, input for counsel and insurance discussions, and a sequenced post-close security plan with clear owners.
Who This Is For
Built for the deal side of the table and for portfolio leaders who need diligence findings translated into decisions and post-close work.
-
Private Equity and Venture Capital
Sponsors evaluating a new investment, monitoring a portfolio company, or preparing an asset for exit.
-
Corporate Acquirers
Deal and integration teams that need to understand inherited cyber risk, regulatory exposure, and post-close priorities.
-
Investment and Capital Partners
Banks, family offices, and direct investors seeking an independent cybersecurity view alongside financial and legal diligence.
-
Portfolio Company Leaders
Management teams preparing for buyer scrutiny or translating diligence findings into an executable remediation plan.
Leadership You Can Trust
Most advisors diagnose. Operators prescribe.
vCSO.ai is led by Nick Shevelyov, former CSO and CIO of Silicon Valley Bank and author of Cyber War and Peace. He brings the perspective of an enterprise operator, board director, and advisor to investors and cybersecurity companies.
Achievements
- Defended Silicon Valley Bank’s cyber posture for 15 years (2007-2021), through every major crisis from the 2008 financial collapse to SolarWinds.
- Design partner and advisor to category-defining cybersecurity companies including Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium.
- Forbes Technology Council member, NASDAQ board director (AuthID), author of Cyber War…and Peace.
- Founder of the CISO Supper Club, convening Bay Area cybersecurity executives twice a year.
Who You’ll Work With
Nick leads the deal-side judgment. Program management, GRC, technical assessment, and product specialists support the scope as the evidence and transaction stage require.
Mike Korsak
Senior Program Management Advisor
Berk Algan
Governance, Risk & Compliance
Andrej Bosanac
Technical Assessments & Pen Testing
Nicholas Carlson
Product & Assessment Platform
Trusted by security leaders
What CISOs, founders, and risk leaders say about working with Nick.
“Nick has been an invaluable partner in elevating Audubon's cybersecurity strategy. His ability to provide clear, level-headed advice has been instrumental during tough moments, and his executive-level communication skills have been particularly effective for the org to plan for right-sized investments in cybersecurity.”
CTO, National Audubon Society
“Nick and team have been amazing partners to Pixee. Their knowledge, relationships, and industry experience have been a core part of our go-to-market strategy and refinement.”
Surag PatelCEO, Pixee
“Nick and team provide a unique value blending cultural enablement and a risk-focused cyber risk management strategy. Their approach helped our team rapidly improve the effectiveness of our cyber risk program with quantifiable results.”
Alexander TraftonSVP Technology Risk and Compliance, G42
FAQ
Questions deal teams ask before engaging.
What is cybersecurity due diligence?
Cybersecurity due diligence evaluates how a target protects critical systems and data, meets its obligations, responds to incidents, and carries risk into a transaction. The purpose is to support the investment decision and post-close plan, not to produce a generic IT audit.
What does the 5-day Initial Risk Review include?
It is a bounded review of the evidence available at that stage of the deal. It identifies visible exposure, material gaps, disclosed incidents and obligations, priority follow-up questions, and the areas that require deeper management-access diligence. Exact coverage is confirmed at intake because source access varies by transaction.
Can you work before management access is available?
Yes, with limitations. An external and document-based review can support an early bid or investment-committee discussion, but it cannot verify internal controls that are not observable or evidenced. Those limitations are stated clearly in the deliverable.
How does Theodolite fit the engagement?
Theodolite can support evidence collection and control review when the target environment, source access, and current product coverage fit. It does not replace interviews, document review, professional judgment, or the need to state evidence gaps.
Do you draft transaction or insurance terms?
No. We explain the cybersecurity findings, likely remediation needs, and decision implications so the deal team, counsel, brokers, and insurers can address them in their own work.
Can you stay involved after close?
Yes. The diligence can lead into a 100-day security plan or ongoing Strategic Oversight for program leadership, remediation governance, and board reporting.
What does the deal team need to know, and by when?
Share the transaction stage, decision date, target profile, and evidence currently available. We will define what can be responsibly concluded in the initial review and what requires deeper access.